Malicious PDF — malware analysis report

Static analysis result for SHA-256 25b01b374032f505…

MALICIOUS

PDF

56.3 KB Created: 2020-08-12 07:49:23 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: c28814dcb3fb8390196722b68627d788 SHA-1: de0e8f780b807d957aa9597882d18b9e1ef3bf7b SHA-256: 25b01b374032f5055e600e4071b537759556001e78bbe955c9259a64df4f6a28
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF contains a critical heuristic firing for a malicious redirector link pointing to 'https://ttraff.com/pify?keyword=ca+cpt+books+pdf+2020'. Additionally, it exhibits characteristics of a PDF link farm, with numerous embedded links to external PDFs, many hosted on shopify.com. The document body, though heavily obfuscated, contains the same redirector URL, reinforcing the lure. The ML classifier strongly indicates maliciousness.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.com/pify?keyword=ca+cpt+books+pdf+2020
    • http://files.spillwaycollective.com/uploads/1/3/1/0/131069789/344e62.pdf
    • http://files.goucherdocc.org/uploads/1/3/2/6/132695714/1278076.pdf
    • http://files.sanmarinogirlscouts.com/uploads/1/3/1/4/131453215/8875701.pdf
    • http://files.lotusranch-homes.com/uploads/1/3/1/4/131407263/5117865.pdf
    • http://wanegolez.thetinyjungle.com/uploads/1/3/2/7/132740748/658abf91bf5.pdf
    • http://files.lotusranch-homes.com/uploads/1/3/1/
    • https://cdn.shopify.com/s/files/1/0432/2023/8503/files/88519214453.pdf
    • https://cdn.shopify.com/s/files/1/0429/6366/5062/files/45122360298.pdf
    • https://cdn.shopify.com/s/files/1/0431/3009/3728/files/pubipulemiwiga.pdf
    • https://cdn.shopify.com/s/files/1/0429/6137/1290/files/sovodetadigonujunavapa.pdf
    • https://cdn.shopify.com/s/files/1/0432/9901/2766/files/didafezetaxakelabukewiju.pdf
    • https://cdn.shopify.com/s/files/1/0431/8865/0142/files/50046754058.pdf
    • https://cdn.shopify.com/s/files/1/0431/0538/6657/files/28965480413.pdf
    • https://cdn.shopify.com/s/files/1/0430/3319/8745/files/2555000044.pdf
    • https://cdn.shopify.com/s/files/1/0439/2691/3179/files/remington_870_express_tactical_shotgun_walmart_price.pdf
    • https://cdn.shopify.com/s/files/1/0439/0119/0299/files/xunuluvamonenapekesisifu.pdf
    • https://cdn.shopify.com/s/files/1/0428/5412/1635/files/kukelaregomiza.pdf
    • https://cdn.shopify.com/s/files/1/0428/3308/4575/files/55345792549.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 4

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off00007287.bin
88cae26229a6670e5542c8356b4b62bdc19e289faf76a66fcbe642fb1165d8ed
pdf-font-stream PDF embedded font (sfnt) at offset 0x7287 5404 bytes
font_01_sfnt_off000084ee.bin
e18682b3fd46480e9666d503c4d562864582807b4e0cbc1ca2988c903de9febe
pdf-font-stream PDF embedded font (sfnt) at offset 0x84EE 2320 bytes
font_02_sfnt_off00008f40.bin
c4c1b61f0490b4626bfb2e46fcaebfc4f52c811a083f335c5178849f87dfc1f4
pdf-font-stream PDF embedded font (sfnt) at offset 0x8F40 14932 bytes
font_03_sfnt_off0000bda6.bin
c3f93d69e3cb30c81ae8f35965ac9f1a1a35941069675b7c0fcc3f03c8d11774
pdf-font-stream PDF embedded font (sfnt) at offset 0xBDA6 16224 bytes